www.infosecurity-magazine.com 6 Oct 2026, 11:41 UTC

ASOS Customers Sent Hack Claim in Push Notification Linking to Telegram

CyberSIXT Evidence Panel Source marked as original reporting

ASOS customers received a curious mobile notification on 6 October 2026 claiming the retailer had been hacked via a Snowflake compromise. The message, appearing as a legitimate ASOS push notification and signed by “xuanyewengateway,” directed recipients to a Telegram link. ASOS has not confirmed any breach at the time of publication. Snowflake is described as a cloud data platform used to store, manage and share data, and the report notes that cyber threat actors frequently target Snowflake-related access.

The piece recalls a May 2024 incident where attackers used stolen credentials to log into Snowflake tenants lacking MFA, and mentions a August 2026 discovery of a critical script-injection vulnerability in Snowflake’s public GitHub repository, reported by Wiz/Google Cloud researchers.

Experts cautioned that, if verified, the incident could imply extensive exposure of customer data and represent a high-profile extortion-style attack. They noted that the ability to push a notification to ASOS app users suggests some foothold in connected systems, though this does not prove the breadth of data accessed. Analysts also highlighted that ASOS’s use of Simon AI for marketing, which runs on Snowflake, creates an indirect link to potential data exposure.

Practical responses advised by the experts include not clicking the link or engaging with the Telegram channel, changing passwords as a precaution, and ASOS reviewing Snowflake audit and authentication logs, assessing data exposure, and following incident response processes with legal and regulatory input. Infosecurity has sought comment from ASOS and Snowflake.

View full article

Article by CyberSIXT